Legal development

Dawn raids: ECJ clarifies rules for email seizures

    On 16 July 2026, the Grand Chamber of the Court of Justice of the European Union (ECJ) delivered its judgment in Joined Cases C-258/23 to C-260/23 (IMI and Others v Autoridade da Concorrência). The judgment confirms that Articles 7 and 8 of the Charter of Fundamental Rights of the European Union (Charter) do not, in principle, preclude the seizure of business emails during inspections by competition law regulators at professional or business premises without prior authorisation by a court, provided that a strict legal framework and adequate safeguards, including full and effective ex post judicial review, are in place. It also requires prior independent review before investigators access data on mobile phones, computers or other storage media belonging to managers or employees, where appropriate after the device has been sealed.

    What you need to know

    • Business emails enjoy fundamental rights protection: Emails exchanged between employees and managers by means of a company’s messaging service constitute communications protected by Article 7 of the Charter. This protection applies whether the emails have been received, read, left unread or deleted, and irrespective of whether their content is private or professional.
    • No prior court authorisation required for business-premises inspections: Articles 7 and 8 of the Charter do not, in principle, preclude the seizure of business emails during an inspection at professional or business premises without prior authorisation by a court, provided that there is a strict legal framework for the authority’s powers to conduct such investigations, and adequate and sufficient safeguards against abuse and arbitrariness, including full and effective ex post judicial review. EU law does not itself require prior court authorisation for such inspections, but Member States may require it under national law.
    • Personal devices require prior independent review: Where inspectors need to access data on mobile phones, computers or other storage media belonging to managers or employees (rather than the company), that access must, where appropriate after the device has been sealed, be subject to prior review by a court or an independent administrative body. The reviewing body must have the powers and guarantees needed to balance the interests of the investigation against the individual’s rights to privacy and data protection.
    • Regulatory procedures may need updating: The judgment reaffirms the long-established authority of competition regulators to conduct dawn raids at business premises. However, authorities may need to revisit their procedures for accessing and reviewing communications stored on personal devices that have been used for business purposes, to ensure compliance with the new requirement for prior independent review.

    Dawn raids

    A ‘dawn raid’ is an unannounced on-site inspection carried out by a competition authority investigating suspected infringements of the antitrust rules. Investigators arrive without advance warning, present a formal inspection decision or authorisation issued by the authority, and may examine and copy business records, including paper files, emails and other electronic data held on company systems. Digital evidence, particularly email, is now an important source of information in many inspections; that is the backdrop against which this judgment was delivered.

    Background on the Portuguese references

    The case originated in three separate investigations by the Autoridade da Concorrência, the Portuguese competition authority (AdC), into suspected infringements of Articles 101 and 102 of the Treaty on the Functioning of the European Union (TFEU):

    • a suspected concerted practice in the pricing of teleradiology services supplied to hospitals belonging to the national health service (IMI, Case C-258/23);
    • a suspected agreement on the pricing of COVID-19 tests procured by Portuguese health authorities (Synlabhealth II, Case C-259/23); and
    • a suspected abuse of a dominant position in payment processing (SIBS group, Case C-260/23).

    Between January 2021 and March 2022, the AdC carried out unannounced inspections at the premises of the companies concerned, authorised in advance by the Portuguese Public Prosecutor's Office. During those inspections, the AdC examined employees' emails and seized almost 13,000 computer files. The companies challenged the lawfulness of the inspections before the Tribunal da Concorrência, Regulação e Supervisão (the Portuguese Competition, Regulation and Supervision Court), which in turn referred three questions to the ECJ for a preliminary ruling.

    In essence, the referring court asked:

    • whether business emails exchanged between employees and managers, and the business records resulting from those communications, constitute communications within the meaning of Article 7 of the Charter;
    • whether Article 7 precludes the seizure of those records in a competition investigation; and
    • whether the answer differs where the seizure was authorised in advance by the Public Prosecutor's Office rather than by a judge.

    The ECJ's judgment

    The ECJ examined the second and third questions together, and assessed whether Articles 7 and 8 of the Charter preclude the seizure of business emails without prior authorisation issued by a court during an inspection at the professional or business premises of undertakings. The full text of the ECJ's judgment is available here.

    Business emails are protected communications

    The ECJ held that business emails exchanged between employees and managers by means of an undertaking’s messaging service constitute communications protected by Article 7 of the Charter. Article 7 guarantees everyone's right to respect for their private and family life, their home and their communications. Drawing on the case law of the European Court of Human Rights, the Grand Chamber confirmed that the same protection applies to communications sent from business premises as to communications sent from a private home. The protection does not depend on:

    • whether an email has been read, remains unread, or has been deleted;
    • whether the communication was sent from business premises or equipment, or using a business email account;
    • whether the sender or recipient is a natural or a legal person; or
    • whether its content is private or purely professional.

    Nor is it relevant that a company has instructed staff not to use its email system for personal purposes: that internal rule governs permitted use of the system, but does not determine whether communications sent through it attract Charter protection. Drawing on WebMindLicenses (C-419/14), the ECJ confirmed that seizure of emails interferes with the right to respect for communications. Article 8 of the Charter is engaged in parallel because personal data relating to the traffic generated by business emails remains personal data, even in a professional context.

    Justifying the interference: the four-part test

    Having established that seizure of business emails interferes with the rights under Articles 7 and 8 of the Charter, the ECJ turned to whether that interference could be justified under Article 52(1) of the Charter.

    That provision permits limitations on fundamental rights only where they are provided for by law, respect the essence of those rights and, subject to the principle of proportionality, are necessary and genuinely meet an objective of general interest recognised by the EU or the need to protect the rights and freedoms of others. Applying each of these four conditions in turn, the ECJ concluded that the seizure was justified:

    • Legality: The measures rested on clear provisions of Portuguese competition law empowering the AdC to search and seize documents, regardless of medium, where necessary to preserve evidence.
    • Essence of the rights: Under Article 7 of the Charter, the measures sought only to access professional emails relating to the investigation, in principle excluding private and family life. Under Article 8 of the Charter, the seizure would not affect the essence of the right where EU law, including the General Data Protection Regulation (Regulation (EU) 2016/679, GDPR), limits the purposes of processing and governs data retention and transfer.
    • Objective of general interest: The investigative and seizure powers of national competition authorities serve to protect undistorted competition in the internal market, an objective of general interest recognised by the EU.
    • Proportionality: Business emails are one of the main sources for detecting anticompetitive conduct. The ECJ found no equally effective, less prejudicial alternative; depriving authorities of this power would risk undermining enforcement of Articles 101 and 102 TFEU.

    No prior court authorisation required under EU law, but strict safeguards apply

    The ECJ concluded that EU law does not require prior authorisation by a court or an independent administrative body for an inspection at business premises, including where emails are seized. Article 20(6) and (7) of Regulation (EC) No 1/2003 and Article 6(3) of Directive (EU) 2019/1 do not impose such a requirement; they leave it to Member States to decide whether to require prior authorisation under national law.

    Where no prior court authorisation is obtained, the ECJ requires the national legal framework to provide:

    • a strict legal framework governing the authority’s powers, with sufficient safeguards against abuse and arbitrariness;
    • effective ex post judicial review allowing a court to examine fully the lawfulness and necessity of the measure, both in fact and in law, to provide appropriate redress and to assess the admissibility of the evidence gathered;
    • a duly reasoned inspection decision based on reasonable grounds to suspect that the undertaking has infringed the competition rules; and
    • where forensic software is used, keyword-based indexing limited to the predetermined subject matter of the investigation.

    National competition authorities must also comply with applicable EU data-protection law, including the GDPR, when processing the data they collect. This includes rules governing the purposes, retention and transfer of that data.

    On the facts before it, the ECJ treated the Portuguese Public Prosecutor's Office as an independent authority capable of exercising prior oversight. Its authorisation contributed to the strict legal framework by defining the appropriateness, duration and material scope of the inspections and seizures. However, because that authorisation was not issued by a court, the ECJ stressed that data subjects must have access to full ex post judicial review meeting the requirements above.

    A higher bar for personal devices

    The Grand Chamber drew a distinction for inspections involving mobile phones, computers or other storage media belonging to individual managers or employees rather than to the undertaking. Such devices may be used for both private and professional purposes. Access may reveal traffic and location data, photographs, browsing history, private communications and information about an individual’s daily habits, movements, relationships and social environment, potentially including special categories of personal data under Article 9 of the GDPR. The ECJ considered that this creates a risk of serious, or even particularly serious, interference with the rights protected by Articles 7 and 8 of the Charter.

    Accordingly, where investigators need to access data on such a device, that access must, where appropriate after the device has been sealed, be subject to prior review by a court or an independent administrative body with all powers and guarantees necessary to strike a fair balance between the legitimate interests of the investigation and the individual's rights to privacy and data protection.

    Practical implications for companies

    The judgment confirms that corporate email systems may be examined during an EU dawn raid even where no court has authorised the inspection in advance. Companies should focus on monitoring and recording the scope of the search, raising objections in real time where appropriate, and preserving their ability to seek full ex post judicial review.

    Personal devices: know the boundary

    The judgment draws a clear distinction between company-owned systems and devices belonging to individuals. Where a device belongs to an employee or manager, access to the data on it must, where appropriate after the device has been sealed, be subject to prior review by a court or an independent administrative body.

    It remains ambiguous whether competition authorities can obtain advance blanket authorisation to access personal devices during a dawn raid or must instead wait until the specific devices have been seized or identified before seeking such permission. In our view, the ECJ's ruling means that where European Commission officials seek to access data on personal devices used for professional reasons during an inspection, such access must be subject to prior review by a court or an independent administrative authority. In the UK, the Competition and Markets Authority has the ability to require the production of copies of relevant information held on personal devices accessible from business premises under inspection, but a warrant is required to enter and search domestic premises, or to take a copy of a personal device away from any premises.

    Companies should:

    • be able to identify personal devices quickly during an inspection, since the distinction carries direct legal consequences;
    • consider whether business communications should be limited to company-issued devices; and
    • where bring-your-own-device arrangements exist, establish clear controls for business communications on personal devices and, where possible, keep personal messaging applications and email accounts separate from business use to ensure the boundary between business and private data remains clear.

    Privilege and post-raid documentation

    • Legally privileged material should be clearly marked and readily identifiable;
    • External counsel should be instructed as soon as an inspection begins so that objections to scope can be raised and recorded in real time; and
    • A structured post-raid debrief should record what was searched, copied, or sealed; this record can support any subsequent ex post judicial review.

    Preparation is key

    Ultimately, a company's response to a dawn raid is only as good as its preparation for one. Reception staff, IT personnel, and the designated response team should each know their role before an inspection ever begins, so that the company can cooperate fully with investigators while still preserving its ability to object to overreach in real time. Regular training and, where possible, simulated exercises remain the most reliable way of turning the principles set out in this judgment into a response that holds up in practice. Companies whose dawn raid protocols have not been reviewed recently may find it useful to consult our Dawn Raid Quickguide and ensure that our companion app, Ashurst Raid Assist, is available on the App Store and ready on the devices of those who would be first to greet inspectors.

    Want to know more?

    Authors: Sergej Bräuer, Partner; Duncan Liddell, Partner; Chris Eberhardt, Partner; Dimitra Karakioulaki; Associate; Sarah Schaible, Transaction Lawyer and Aamir Hajjout, Research Assistant.

    The information provided is not intended to be a comprehensive review of all developments in the law and practice, or to cover all aspects of those referred to.
    Readers should take legal advice before applying it to specific issues or transactions.